Senior GRC Analyst

Posted An Hour Ago
Be an Early Applicant
Kraków, Małopolskie, POL
In-Office
Senior level
Financial Services
The Role
Lead governance and assurance of the Information Security Program, aligning with frameworks (NIST CSF, ISO27001). Quantify and integrate cyber risk into Enterprise Risk Management, map controls to GDPR, DORA and banking regulations, liaise with auditors, develop security training, and implement/operate modern GRC tools to manage compliance and remediation.
Summary Generated by Built In

Fancy helping to shape the future of FinTech?
We have always been innovators. In 1996 we were the first company to share exchange rate information, free of charge on the internet. Today, we are a world leading online trading group.


Join us to:

  • Help build the future of online trading 
  • Be part of a culture driven by integrity and global impact
  • Become part of an award-winning company - check out our full list of awards here

We are only as good as our people. Luckily, our people are the best. Join us! 


How do we work?

We implement governance and assurance of the Information Security Program, including the measurement of its adoption, performance, and maturity. We provide oversight of security stakeholders along with their related processes and documentation, ensuring that the Information Security Program is aligned with regulatory requirements, identified security frameworks (NIST CSF, ISO27001:2022), and relevant data protection requirements. In our daily operations, we oversee FTMO Group’s Cyber Risk Management, ensuring that Cyber Risk processes and metrics are seamlessly integrated into the Enterprise Risk Management Framework. We ensure strict compliance with FTMO Group’s internal controls, regulatory requirements, and information security policies and procedures. To achieve this, we work closely with internal audit, compliance teams, external audit firms, and regulatory agencies to provide supportive documentation as applicable.

This role is available on a B2B contract basis. 

In this role, you will:

  • Take ownership of the Information Security Program's governance, ensuring alignment with key frameworks like NIST CSF and ISO27001:2022.

  • Quantify and track cyber risks, seamlessly integrating them into our broader Enterprise Risk Management framework.

  • Stay ahead of the curve by mapping our security program against critical regulatory requirements, including GDPR, DORA, and global Banking Authority guidelines in countries where FTMO Group operates.

  • Champion our security culture by creating and delivering engaging training materials to defend against threats like malware, phishing, and physical security risks.

  • Act as the key point of contact for internal and external auditors, responding to regulatory questionnaires and leading the remediation of any security gaps.

  • Streamline and automate our GRC processes by implementing and supporting modern GRC tools.

What skillset do you need to be successful in this role?

  • 5 to 10 years of hands-on experience specifically in the information security industry.

  • Strong working knowledge of major security frameworks and standards, such as SOC2, ISO27001, NIST, and PCI-DSS.

  • Deep understanding of data protection and sectorial regulations, specifically GDPR and DORA.

  • Proven experience performing risk assessments, writing security policies, and managing compliance.

  • Excellent communication skills to lead security meetings, present clear action plans to senior management, and persuade stakeholders.

Nice to have: 

  • Industry credentials like CISSP, CRISC, CISA, CISM, or ISO27001 Lead Auditor/Implementer, as well as a relevant university degree.

  • Prior experience in the financial industry, especially with regulations surrounding leveraged trading products, is a strong plus.

___

At OANDA, to help us efficiently process applications, we use AI-driven tools to help source and rank candidates based on professional experience and skills. While these tools provide recommendations, our recruitment process remains human-centric: all final shortlisting and hiring decisions are made by OANDA team. You have the right to request a human review of your application.

OANDA Global Corporation is a diverse and global team with offices around the world. We value the unique skills and experiences each individual brings to OANDA. We are committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide an inclusive and accessible environment for everyone. Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment and selection process, please let us know. We will work with you to provide as seamless a recruitment experience as possible.

Learn more about our culture here.

Review OANDA Privacy Policy and learn more about how we treat your personal data and protect your privacy. 

Skills Required

  • 5 to 10 years hands-on experience in information security
  • Strong working knowledge of SOC2, ISO27001, NIST, and PCI-DSS
  • Deep understanding of data protection and sectoral regulations, specifically GDPR and DORA
  • Proven experience performing risk assessments, writing security policies, and managing compliance
  • Experience integrating cyber risk into an Enterprise Risk Management framework
  • Experience implementing and supporting modern GRC tools
  • Excellent communication skills to lead security meetings and present to senior management
  • Industry credentials (CISSP, CRISC, CISA, CISM, ISO27001 Lead Auditor/Implementer)
  • Relevant university degree
  • Prior experience in the financial industry, especially with leveraged trading products
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto, CA
632 Employees
Year Founded: 1996

What We Do

Everyone at OANDA is focused on our vision to transform how our customers can meet all their currency needs. From our roots in 1996 that provided free currency exchange information to launching a multi-award winning global FX and CFD trading business to our recent new venture of money transfer. OANDA is now a major global player. Innovation has been at the heart of everything we do and our approach is to pioneer intuitive, user-friendly products supported by our great customer service ethos. We’ve come a long way since our first data feed went live in 1996, and we still have so much more that we want to achieve. Substantial funding has facilitated our exceptional growth. In 2007 we received $100M USD in Series B funding and in 2018 were acquired by CVC Capital Partners Asia Fund IV. For more information, please visit oanda.com. You can follow us on Twitter, Facebook, or YouTube. Leveraged trading is high risk and may not be suitable for everyone as your losses may exceed your investment.

Similar Jobs

Ericsson Logo Ericsson

System Developer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Kraków, Małopolskie, POL
88000 Employees

Capco Logo Capco

Murex Test Manager (MxTest)

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Capco Logo Capco

Senior Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Capco Logo Capco

Senior Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account